FTSE 350 firms on a par with global peers
Monthly Archives: April 2023
rnp-0.16.3-1.el9
FEDORA-EPEL-2023-97d6b10e34
Packages in this update:
rnp-0.16.3-1.el9
Update description:
Version 0.16.3 (2023-04-11)
Security
Fixed issue with possible hang on malformed inputs (CVE-2023-29479).
Fixed issue where in some cases, secret keys remain unlocked after use (CVE-2023-29480).
rnp-0.16.3-1.fc37
FEDORA-2023-0b5ccd1812
Packages in this update:
rnp-0.16.3-1.fc37
Update description:
Version 0.16.3 (2023-04-11)
Security
Fixed issue with possible hang on malformed inputs (CVE-2023-29479).
Fixed issue where in some cases, secret keys remain unlocked after use (CVE-2023-29480).
rnp-0.16.3-1.fc36
FEDORA-2023-609db87741
Packages in this update:
rnp-0.16.3-1.fc36
Update description:
Version 0.16.3 (2023-04-11)
Security
Fixed issue with possible hang on malformed inputs (CVE-2023-29479).
Fixed issue where in some cases, secret keys remain unlocked after use (CVE-2023-29480).
rnp-0.16.3-1.fc38
FEDORA-2023-cf4df6380b
Packages in this update:
rnp-0.16.3-1.fc38
Update description:
Version 0.16.3 (2023-04-11)
Security
Fixed issue with possible hang on malformed inputs (CVE-2023-29479).
Fixed issue where in some cases, secret keys remain unlocked after use (CVE-2023-29480).
rnp-0.16.3-1.el8
FEDORA-EPEL-2023-78b54db021
Packages in this update:
rnp-0.16.3-1.el8
Update description:
Version 0.16.3 (2023-04-11)
Security
Fixed issue with possible hang on malformed inputs (CVE-2023-29479).
Fixed issue where in some cases, secret keys remain unlocked after use (CVE-2023-29480).
USN-6012-1: Smarty vulnerability
It was discovered that Smarty incorrectly parsed blocks’ names and
included files’ names. A remote attacker with template writing permissions
could use this issue to execute arbitrary PHP code. (CVE-2022-29221)
ZDI-23-439: Linux Kernel RxRPC Race Condition Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
ZDI-23-440: Linux Kernel DPT I2O Controller Time-Of-Check Time-Of-Use Information Disclosure Vulnerability
This vulnerability allows local attackers to disclose sensitive information on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability.
ZDI-23-441: Linux Kernel udmabuf Improper Validation of Array Index Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability.